GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,863
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,585
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
3,337 advisories
Filter by severity
Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls
High
CVE-2026-101898
was published
for
axios
(npm)
Sep 30, 2026
A flaw was found in Moodle. Incorrect handling of IPv4-mapped IPv6 addresses within the URL...
Moderate
Unreviewed
CVE-2026-102577
was published
Sep 30, 2026
The Broken Link Notifier WordPress plugin before 2.0.0.1 does not re-validate the destination of...
Moderate
Unreviewed
CVE-2026-97316
was published
Sep 30, 2026
PyJWT: PyJWKClient follows redirects when fetching JWKS
High
CVE-2026-102267
was published
for
PyJWT
(pip)
Sep 29, 2026
Fider before 0.38.0 contains a server-side request forgery vulnerability due to a time-of-check...
Low
Unreviewed
CVE-2026-102877
was published
Sep 29, 2026
ClaraVerse through 0.3.1 contains server-side request forgery protection bypasses in the...
Moderate
Unreviewed
CVE-2026-102879
was published
Sep 29, 2026
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, an unauthenticated network check function can...
Moderate
Unreviewed
CVE-2026-100297
was published
Sep 29, 2026
In the IPv4 PASV path, the FTP Client accepts whatever address was sent in the server's `227`...
Moderate
Unreviewed
CVE-2026-102722
was published
Sep 29, 2026
Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in Joomla 4.0.0-5.4.8,...
High
Unreviewed
CVE-2026-92222
was published
Sep 29, 2026
A security flaw has been discovered in MODSetter SurfSense up to 0.0.36. Impacted is an unknown...
Low
Unreviewed
CVE-2026-102244
was published
Sep 29, 2026
ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts
Moderate
CVE-2026-101913
was published
for
ip-address
(npm)
Sep 28, 2026
ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass
Moderate
CVE-2026-101910
was published
for
ip-address
(npm)
Sep 28, 2026
jackson-databind: Incomplete fix for CVE-2026-54514: eager DNS resolution (SSRF) still present in InetAddress deserialization
Moderate
CVE-2026-77310
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Sep 28, 2026
Server-Side Request Forgery (SSRF) in Apache Roller 6.1.5 allows an authenticated user with entry...
High
Unreviewed
CVE-2026-82375
was published
Sep 28, 2026
Joomla Extension - regularlabs.com - LFI / SSRF in Modules Anywhere 1.5.0 - 9.0.5 for Joomla -...
High
Unreviewed
CVE-2026-100750
was published
Sep 28, 2026
A vulnerability was detected in October CMS up to 4.3.4. This affects the function...
Moderate
Unreviewed
CVE-2026-101005
was published
Sep 28, 2026
A vulnerability was found in OctoberCMS up to 4.1.19/4.2.25/4.3.4. The impacted element is the...
Moderate
Unreviewed
CVE-2026-100909
was published
Sep 28, 2026
A vulnerability has been found in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/v2.0.0...
Low
Unreviewed
CVE-2026-100900
was published
Sep 28, 2026
A vulnerability was found in athlon1600 youtube-downloader up to 4.0.1. Affected by this...
Moderate
Unreviewed
CVE-2026-100901
was published
Sep 28, 2026
A vulnerability was determined in Privoce VoceChat Server up to 0.5.36. This vulnerability...
Moderate
Unreviewed
CVE-2026-100893
was published
Sep 28, 2026
Nezha versions 2.0.10 through 2.3.2 use a restricted HTTP client to validate user-configurable...
Moderate
Unreviewed
CVE-2026-101087
was published
Sep 27, 2026
Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server...
High
Unreviewed
CVE-2026-101064
was published
Sep 27, 2026
utcp-http before 1.1.4 fails to validate the OAuth2 tokenUrl field from remote OpenAPI...
High
Unreviewed
CVE-2026-101059
was published
Sep 27, 2026
utcp-gql before 1.1.1 and utcp-websocket before 1.1.1 contain server-side request forgery...
Low
Unreviewed
CVE-2026-101061
was published
Sep 27, 2026
python-utcp versions before 1.1.4 contain a server-side request forgery vulnerability in...
High
Unreviewed
CVE-2026-101060
was published
Sep 27, 2026
ProTip!
Advisories are also available from the
GraphQL API